The ARCEUSULP Dump Put 292,054 Stolen Email Logins Online
In June 2026, HEROIC analysts identified a combolist named ARCEUSULP 133 734053, uploaded to Telegram by an individual user. The file held 292,054 records combining email addresses, plaintext passwords, and the URLs where each login was used. Why is this dangerous? With nearly 300,000 plaintext email and password pairs in one file, an attacker can automate login attempts across hundreds of websites at once. Anyone whose credentials appear in the ARCEUSULP file is exposed the moment someone downloads it, since no password cracking is needed. Here is what was exposed in the ARCEUSULP leak: email addresses, plaintext passwords, and associated URLs. Why this matters: A file of this size is large enough to be fed directly into automated credential-stuffing tools, which test stolen logins against banks, email providers, and retailers in bulk, often within hours of the file being posted. Stolen credentials like these rarely stay in one place. Attackers feed lists like this into automated tools that test each email and password pair against banking sites, email providers, and online retailers, a technique known as credential stuffing. When a password is reused, one exposed account can lead directly to account takeover, identity theft, or financial fraud on completely unrelated services. How a Combolist This Large Gets Assembled: Large combolists like ARCEUSULP are typically built by merging data from several smaller breaches, phishing kits, and malware infections into one master file, then cleaning and formatting it so the entries are easy to search and reuse. The scale of this file, 292,054 records, suggests it draws from multiple prior sources rather than a single incident. Check If Your Login Is Among the 292,054 Exposed Records: You do not have to wait to find out if your information is part of a leak like this one. HEROIC's free breach scanner checks your email address against a database of more than 400 billion exposed records, including combolists and stealer logs like this one, and tells you immediately if your credentials have shown up in a known breach. If you find a match, change that password right away, and avoid reusing it anywhere else.
Breach Breakdown
292,054 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds